github.com/hashicorp/consul vulnerabilities
CVEs whose affected-version data names the github.com/hashicorp/consul package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2025-11374Medium· 6.5Consul key/value endpoint is vulnerable to denial of service
Consul key/value endpoint is vulnerable to denial of service
CVE-2023-3518High· 7.4Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
CVE-2023-0845Medium· 6.5Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
CVE-2022-3920High· 7.5Missing Authorization in HashiCorp Consul
Missing Authorization in HashiCorp Consul
CVE-2021-41803High· 7.1HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
CVE-2018-19653Medium· 5.9HashiCorp Consul can use cleartext agent-to-agent RPC communication
HashiCorp Consul can use cleartext agent-to-agent RPC communication
CVE-2021-38698Medium· 6.5HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.
CVE-2021-32574High· 7.5Hashicorp Consul Missing SSL Certificate Validation
Hashicorp Consul Missing SSL Certificate Validation
CVE-2020-7219High· 7.5Denial of Service (DoS) in HashiCorp Consul
Denial of Service (DoS) in HashiCorp Consul